OpenLDAP Groups

Jean Carlos Coelho coelho at teltecsolutions.com.br
Mon Oct 21 18:07:48 CEST 2013


On 21/10/13 12:07, "Arran Cudbard-Bell" <a.cudbardb at freeradius.org> wrote:

>
>On 21 Oct 2013, at 15:07, Arran Cudbard-Bell <a.cudbardb at freeradius.org>
>wrote:
>
>> 
>>> This conf is at "post-auth"? Where can I find some how to's to
>>>configure
>>> this actions (regular expressions)?
>> 
>> Um sure, or in authorize.
>> 
>> man unlang?
>
>Wait you want to use a regex to match groups? That's not possible.

No I am trying to use (configure) something like thisŠ

Wifi lan = 10.10.10.0/24 (company vlan22 [mngmt = vlan1])
Cable lan = 192.168.0.0/24 (company vlan23 [mngmt = vlan1])
Net academy (all school) = 172.16.5.10 (vlan5)

If access TO mngmt switch (or WLC) is from
	vlan22 or vlan23 and primary ldap group for user john equals "ti"
		Then set admin vlan1 mngmt
			And access ok (wlc or switch)
		Else 
			Reject

>
>http://stackoverflow.com/questions/6293231/ldap-search-using-regular-expre
>ssion
>
>Arran Cudbard-Bell <a.cudbardb at freeradius.org>
>FreeRADIUS Development Team
>
>-
>List info/subscribe/unsubscribe? See
>http://www.freeradius.org/list/users.html
>




More information about the Freeradius-Users mailing list